CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,376 vulnerabilities with CWE-287
CVE-2009-1587
PHP Site Lock 2.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2009-1549
AGTC MyShop 3.2b - Unauthenticated Authentication Bypass via log_accept Cookie
CVE-2009-1504
Absolute Form Processor XE 1.5 - Unauthenticated Authentication Bypass via xlaAFPadmin Cookie
CVE-2009-1489
Fungamez RC1 - Unauthenticated Authentication Bypass via User Cookie Parameter
CVE-2009-0662
PlonePAS <3.9-<3.2.2 - Info Disclosure
CVE-2009-1155
Cisco ASA 5500 & PIX VPN Authentication Bypass (7.1-8.1)
CVE-2009-0892
IBM WebSphere Application Server 6.1-7.0 - Session Hijacking via Forced Logout
CVE-2009-0591
OpenSSL 0.9.8h-0.9.8j - Signature Repudiation via Malformed CMS Signed Attributes
CVE-2009-0891
IBM WebSphere Application Server 6.0.2-6.1.0.22 and 7.0 - Session Hijacking via WS-Security Bypass
CVE-2009-1050
Bloginator 1A - Unauthenticated Authentication Bypass via identifyYourself Cookie
CVE-2009-0085
Microsoft Windows - Authentication Bypass
CVE-2009-0864
S-Cms 1.1 Stable - Unauthenticated Authentication Bypass via Login Cookie
CVE-2009-0853
CelerBB 0.0.2 - Authentication Bypass via Username Parameter
CVE-2009-0614
Cisco Unified Meetingplace Web Conferencing < 6.0\(517.0\) - Authentication Bypass
CVE-2009-0440
IBM WebSphere Partner Gateway 6.0.0-6.0.0.7 - Command Injection
CVE-2009-0655
Lenovo Veriface III - Info Disclosure
CVE-2009-0653
OpenSSL - Improper Certificate Validation via Missing Basic Constraints Check
CVE-2009-0642
Ruby 1.8 and 1.9 - Improper Certificate Validation in OCSP Verification
CVE-2009-0360
pam-krb5 <3.13 - Privilege Escalation
CVE-2009-0362
fail2ban - Denial of Service via Crafted Reverse-Resolved DNS Name
CVE-2009-0138
Apple Mac OS X 10.5.6 - Auth Bypass
CVE-2009-0461
Whole Hog Password Protect: Enhanced 1.x - Auth Bypass
CVE-2009-0460
Whole Hog Ware Support 1.x - Auth Bypass
CVE-2009-0492
SimpleIrcBot - Improper Authentication
CVE-2009-0412
Interspire Shopping Cart <4.0.1 - Auth Bypass
Details
Vulnerabilities 4,376
Exploit Likelihood High